Unauthenticated Shell via MAVLink Enables Remote Command Execution

PX4 Autopilot — flight control software for drones and unmanned vehicles — accepts unauthenticated SERIAL_CONTROL MAVLink messages that can spawn an interactive shell. The flaw appears in Autopilot v1.16.0_SITL_latest_stable and is tracked as CVE-2026-1579. MAVLink does not require cryptographic authentication by default, so deployments with MAVLink 2.0 message signing disabled will accept unsigned SERIAL_CONTROL messages. Affected sectors include transportation, defense, and other critical infrastructure where MAVLink interfaces are reachable.

Part of the PlainSec briefing for 2026-04-01

Sources